LEAD-AUDITOR · Question #345
Drag and Drop Question Select the correct sequence for the information security risk assessment process in an ISMS. To complete the sequence click on the blank section you want to complete so that it
The correct answer is Establish information security criteria; Identify the information security risks; Analyze the information security risks; Evaluate the information security risks. ISO 27001 Risk Assessment Sequence Explained This sequence comes directly from ISO/IEC 27001, Clause 6.1.2 (Information security risk assessment). The standard mandates this exact order. --- Why This Order? The logic follows a natural progression: define the rules → find problems
Question
Drag and Drop Question Select the correct sequence for the information security risk assessment process in an ISMS. To complete the sequence click on the blank section you want to complete so that it is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop the options to the appropriate blank. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- Establish information security criteria
- Identify the information security risks
- Analyze the information security risks
- Evaluate the information security risks
Explanation
ISO 27001 Risk Assessment Sequence Explained
This sequence comes directly from ISO/IEC 27001, Clause 6.1.2 (Information security risk assessment). The standard mandates this exact order.
Why This Order?
The logic follows a natural progression: define the rules → find problems → measure them → judge them.
Item-by-Item Breakdown
1. Establish information security criteria (must come first)
You cannot assess risks without knowing what a "risk" means to your organization. This step defines:
- Risk acceptance criteria - what level of risk is tolerable
- Assessment criteria - the scale/methodology used to measure likelihood and impact
Common mistake: Many assume you find risks first, then set criteria. That's backwards - criteria must exist before you can meaningfully identify or measure anything. Without a scale, your findings are arbitrary.
2. Identify the information security risks (discovery phase)
Only after criteria are defined do you scan for risks - identifying:
- Assets, threats, and vulnerabilities
- Potential loss of confidentiality, integrity, or availability
- Risk owners
Common mistake: Conflating "identify" with "analyze." Identification is purely finding risks, not measuring them.
3. Analyze the information security risks (quantify phase)
For each identified risk, you now measure it:
- Assess likelihood of occurrence
- Assess potential consequences (impact)
- Derive a risk level (e.g., High/Medium/Low or a numeric score)
Common mistake: Swapping steps 3 and 4. Analysis produces a risk level - evaluation uses that level. You must have a number before you can judge it.
4. Evaluate the information security risks (decision phase)
Now you compare the risk levels from step 3 against the criteria established in step 1:
- Which risks need treatment?
- Which are acceptable as-is?
- How should risks be prioritized?
Common mistake: Thinking "evaluate" and "analyze" are synonyms. Analyze = measure; Evaluate = judge against criteria. ISO 27001 treats these as explicitly separate activities.
Key Takeaway
The biggest trap on this question is swapping Analyze and Evaluate, or putting Establish criteria anywhere but first. The standard is deliberate: you cannot judge what you haven't measured, and you cannot measure what you haven't defined.
Topics
Community Discussion
No community discussion yet for this question.
